MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-22 · via BleepingComputer

Swedish regulator penalizes IT firm for security gaps behind massive data breach

Image via BleepingComputer
Image via BleepingComputer

Sweden's data protection authority IMY fined IT provider Miljödata approximately $183,000 for failing to implement adequate security measures that led to a cyberattack in August 2025. The breach exposed sensitive personal data of 2.2 million people, including identity numbers and school records, which was later leaked online. IMY found the company lacked proper software vetting and real-time monitoring, violating GDPR Article 32(1).

Expanded Detail

The cyberattack on Miljödata occurred on August 25, 2025, disrupting IT services across more than 200 Swedish regions and exposing records of 2.2 million individuals. The stolen data included personal identity numbers, contact details, sickness absence records, rehabilitation notes, and school incidents involving minors. The attackers initially demanded 1.5 Bitcoin (about $168,000) to prevent publication, but later leaked the information on the dark web under the alias "Datacarry."

IMY's investigation, launched in November 2025, determined that Miljödata failed to properly vet newly installed software and lacked automated real-time monitoring to detect intrusions. This negligence violated GDPR Article 32(1), resulting in the $183,000 fine. The regulator also noted that investigations into two municipalities and one region connected to the attack are still ongoing, meaning additional penalties could be issued against those public entities.

Context

This penalty underscores the serious financial and reputational risks of inadequate security hygiene for vendors handling sensitive public-sector data. The breach affected millions, including minors, so affected individuals could face long-term consequences such as identity theft and privacy violations. IMY's ongoing probes into municipalities suggest accountability may extend beyond the vendor, potentially prompting stricter procurement standards and more rigorous oversight of third-party IT providers. This could lead to higher compliance costs for companies, but also stronger protections for citizens' personal information.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Ireland imposes €403M GDPR penalty on Google for location tracking breaches · Cybersecurity
Image-sharing platform Gyazo hit by breach affecting 23.6 million accounts · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Sweden fines Miljödata $183,000 over breach affecting 2.2 million.” Browse more stories.